Content area

Abstract

The adoption and popularity of mobile devices by end-users is partially driven by the increasing development and availability of mobile applications that can aid solving different problems and provide access to services in a wide range of domains or categories, namely healthcare, education, e-commerce or entertainment. While these applications use and benefit from the combination of a wide panoply of technologies from the Internet of Things, fog and cloud computing, data security and privacy are typically not fully taken into account before the creation of many mobile applications or during the software development phases. This paper presents an in-depth approach to modeling attacks on the specific cloud and mobile ecosystem, given its importance in the process of secure application development. Moreover, aiming at bridging the knowledge gap between developers and security experts, this paper presents an alpha version of the security by design for cloud and mobile ecosystem (secD4CloudMobile) framework. secD4CloudMobile is a set of tools that covers cloud and mobile security requirement elicitation (CMSRE), cloud and mobile security best practices guidelines (CMSBPG), cloud mobile attack modeling elicitation (CMAME), and cloud mobile security test specification and tools (CM2ST). The purpose of the framework is to provide cloud and mobile application developers useful readily applicable information and guidelines, striving to bring security engineering and software engineering closer, in a more accessible and automated manner, aiming at the incorporation of security by construction. Finally, the paper presents some preliminary results and discussion.

Details

10000008
Title
Expediting the design and development of secure cloud-based mobile apps
Author
Chimuco, Francisco T. 1 ; Sequeiros, Joāo B. F. 2 ; Simōes, Tiago M. C. 2 ; Freire, Mário M. 2 ; Inácio, Pedro R. M. 2 

 Universidade da Beira Interior and Instituto de Telecomunicações, Covilhã, Portugal (GRID:grid.7427.6) (ISNI:0000 0001 2220 7094); Instituto Superior de Ciências de Educação da Huíla, Lubango, Angola (GRID:grid.7427.6) 
 Universidade da Beira Interior and Instituto de Telecomunicações, Covilhã, Portugal (GRID:grid.7427.6) (ISNI:0000 0001 2220 7094) 
Publication title
Volume
23
Issue
4
Pages
3043-3064
Publication year
2024
Publication date
Aug 2024
Publisher
Springer Nature B.V.
Place of publication
Heidelberg
Country of publication
Netherlands
Publication subject
ISSN
16155262
e-ISSN
16155270
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2024-07-04
Milestone dates
2024-06-22 (Registration)
Publication history
 
 
   First posting date
04 Jul 2024
ProQuest document ID
3080012027
Document URL
https://www.proquest.com/scholarly-journals/expediting-design-development-secure-cloud-based/docview/3080012027/se-2?accountid=208611
Copyright
© The Author(s) 2024. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-11-19
Database
ProQuest One Academic